← Back to CVE List

CVE-2018-18258

Published: 2018-10-11T21:01Z
Last Modified: 2024-11-21T03:55Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via an index.php?r=admini/template/updateTpl&filename= URI. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt